Aller au contenu

Fiche vulnérabilité

CVE-2025-2352 : faille moyenne starsea99 starsea-mall (CVSS 5.4)

Description

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of the component Backend. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
16 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • starsea99 starsea-mall

Références

Rechercher une autre vulnérabilité dans la base CVE